5.3

CVSS3.1

CVE-2025-3609 - Reales WP STPT <= 2.1.2 - Unauthorized User Registration

The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to the 'reales_user_signup_form' AJAX action not verifying if user registration is enabled, prior to registering a user. This makes it possible for unauth…

πŸ“… Published: May 6, 2025, 1:42 a.m. πŸ”„ Last Modified: April 20, 2026, 11 p.m.

8.8

CVSS3.1

CVE-2025-3610 - Reales WP STPT <= 2.1.2 - Authenticated (Subscriber+) Privilege Escalation via Password Update

The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for authenticated…

πŸ“… Published: May 6, 2025, 1:42 a.m. πŸ”„ Last Modified: April 21, 2026, 9 p.m.

5.3

CVSS4.0

CVE-2025-4305 - kefaming mayi File.php upload unrestricted upload

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file app/tools/controller/File.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has…

πŸ“… Published: May 6, 2025, 1:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4304 - PHPGurukul Cyber Cafe Management System adminprofile.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit …

πŸ“… Published: May 6, 2025, 1:31 a.m. πŸ”„ Last Modified: May 13, 2025, 7:21 p.m.

6.2

CVSS3.1

CVE-2024-39442 -

In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

πŸ“… Published: May 6, 2025, 1:07 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-4303 - PHPGurukul Human Metapneumovirus Testing Management System add-phlebotomist.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql injection. The attack may …

πŸ“… Published: May 6, 2025, 1 a.m. πŸ”„ Last Modified: May 8, 2025, 7:03 p.m.

7.8

CVSS3.1

CVE-2025-2509 -

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.

πŸ“… Published: May 6, 2025, 12:59 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.

7.5

CVSS3.1

CVE-2025-46728 - cpp-httplib has Unbounded Memory Allocation in Chunked/No-Length Requests

cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunk…

πŸ“… Published: May 6, 2025, 12:45 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 9:25 p.m.

6.9

CVSS4.0

CVE-2025-4301 - itsourcecode Content Management System search-notice.php sql injection

A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exp…

πŸ“… Published: May 6, 2025, 12:31 a.m. πŸ”„ Last Modified: May 13, 2025, 8:21 p.m.

6.9

CVSS4.0

CVE-2025-4300 - itsourcecode Content Management System search_list.php sql injection

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been discl…

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:22 p.m.
Total resulsts: 346534
Page 5279 of 34,654
Β« previous page Β» next page
Filters